<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: firewall using wrong LDAP attribute to find user in active directory in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-using-wrong-ldap-attribute-to-find-user-in-active/m-p/279673#M75747</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/24977"&gt;@Carracido&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is your LDAP server profile configured correctly? Do you use the LDAP profile also for User-ID group mapping settings and if yes, does it work there correctly? Did you set the type to active-directory?&lt;/P&gt;</description>
    <pubDate>Sun, 28 Jul 2019 08:54:26 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2019-07-28T08:54:26Z</dc:date>
    <item>
      <title>firewall using wrong LDAP attribute to find user in active directory</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-using-wrong-ldap-attribute-to-find-user-in-active/m-p/276404#M75356</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I´d like to check with you the following issue:&lt;/P&gt;&lt;P&gt;created a LDAP authentication profile which is not working, when using the "test.... " command I get an authentication failed with "&lt;SPAN&gt;Received empty DN for user User12345"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I made a traffic capture and saw that the&amp;nbsp;firewall is using the wrong attribute to find the user on the active directory. The firewall is using the&amp;nbsp;"uid" attribute to authenticate the user but&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;PAN firewalls can use only the following login attributes for LDAP authentication:&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClogCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClogCAC&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If I have the "sAMAccountName" login attribute in my authentication profile, why is the firewall even trying to search the active directory with "uid" attribute? Any idea?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Carracido.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2019 20:43:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-using-wrong-ldap-attribute-to-find-user-in-active/m-p/276404#M75356</guid>
      <dc:creator>Carracido</dc:creator>
      <dc:date>2019-07-12T20:43:54Z</dc:date>
    </item>
    <item>
      <title>Re: firewall using wrong LDAP attribute to find user in active directory</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-using-wrong-ldap-attribute-to-find-user-in-active/m-p/279673#M75747</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/24977"&gt;@Carracido&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is your LDAP server profile configured correctly? Do you use the LDAP profile also for User-ID group mapping settings and if yes, does it work there correctly? Did you set the type to active-directory?&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jul 2019 08:54:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-using-wrong-ldap-attribute-to-find-user-in-active/m-p/279673#M75747</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2019-07-28T08:54:26Z</dc:date>
    </item>
  </channel>
</rss>

